New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
ID: abae2907-69cb-5f0e-8ef8-22ccf69ad756
STIX ID: report--abae2907-69cb-5f0e-8ef8-22ccf69ad756
Feed Name: The Hacker News
A heap-based buffer overflow (CVE-2026-14266) in 7-Zip's XZ decoder can allow code execution if a victim opens a crafted XZ archive; the flaw stems from incorrect output-buffer length handling in MixCoder_Code and was fixed in 7-Zip 26.02. ZDI rates it 7.0 (High) but the attack vector is local (AV:L), has high complexity, requires user action, and as of July 20, 2026 there is no public proof-of-concept or reported exploitation in the wild — administrators should manually update any systems or vendors that bundle the vulnerable decoder.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
